[PATCH 1/1] libnvme: TLS PSK derivation fixes

Chris Leech cleech at redhat.com
Mon Jul 21 08:31:58 PDT 2025


On Mon, Jul 21, 2025 at 08:36:01AM +0200, Hannes Reinecke wrote:
> On 7/21/25 04:17, Chris Leech wrote:
> > There are issues with the Retained and TLS PSK derivations due to the
> > implementation not adhering to the RFC 8446 definition of the
> > HKDF-Expand-Label function.
> > ...
> Hmm. I _thought_ we had it all fixed...

I went into this expecting/hoping to find the problem on the spdk side,
and I'd be happy to wrong here (especially if backed up by another
interoperable implementor).

The lack of a full example in the nvme/tcp transport spec to verify
implemenatations against is kind of a bummer.

- Chris




More information about the Linux-nvme mailing list